What's in this manual
What's in this manual
In this manual, you'll find information and procedures for the Splunk enterprise user—if you use Splunk to investigate problems and report on results, this is the manual for you.
Continue reading to:
- learn how to add data to your indexes
- start searching with terms, Boolean expressions, and fields
- learn how to use the search results and timeline to interactively narrow your search
- learn how to save event types, extract new fields, and tag field values
- learn how to save searches and set alert conditions for scheduled searches
- start building reports and charts to save and share with others
if you want to just jump right in and start searching, see the Search command cheat sheet for a quick reference complete with descriptions and examples.